« Volver al listado

CVE-2021-41994

Estado: ModificadaMedia (4.8)—

A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-41994",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 1.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "responsible-disclosure@pingidentity.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.6,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 0.3
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.8,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 0.4
      }
    ]
  },
  "affected": [
    {
      "source": "responsible-disclosure@pingidentity.com",
      "affectedData": [
        {
          "vendor": "Ping Identity",
          "product": "PingID Mobile Application",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "1.19",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "iOS"
          ]
        }
      ]
    }
  ],
  "published": "2022-04-30T22:15:08.203",
  "references": [
    {
      "url": "https://docs.pingidentity.com/bundle/pingid/page/ejd1642076304199.html",
      "tags": [
        "Patch",
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "responsible-disclosure@pingidentity.com"
    },
    {
      "url": "https://www.pingidentity.com/en/resources/downloads/pingid.html",
      "tags": [
        "Patch"
      ],
      "source": "responsible-disclosure@pingidentity.com"
    },
    {
      "url": "https://docs.pingidentity.com/bundle/pingid/page/ejd1642076304199.html",
      "tags": [
        "Patch",
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.pingidentity.com/en/resources/downloads/pingid.html",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "responsible-disclosure@pingidentity.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-330"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A misconfiguration of RSA in PingID iOS app prior to 1.19 is vulnerable to pre-computed dictionary attacks, leading to an offline MFA bypass when using PingID Windows Login."
    },
    {
      "lang": "es",
      "value": "Una configuración errónea de RSA en la aplicación PingID para iOS versiones anteriores a 1.19, es vulnerable a ataques de diccionario precalculado, conllevando a una omisión de MFA sin conexión cuando es usado PingID Windows Login"
    }
  ],
  "lastModified": "2026-06-17T04:09:07.867",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pingidentity:pingid:*:*:*:*:*:iphone_os:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57303B0B-A2A3-4A9F-BFE8-6F1A7B21D324",
              "versionEndExcluding": "1.19"
            },
            {
              "criteria": "cpe:2.3:a:pingidentity:pingid_windows_login:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6DEAA503-7CDB-44B1-9A37-89D9ED8149D5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "responsible-disclosure@pingidentity.com"
}